【資安漏洞預警】Cisco旗下Integrated Management Controller 存在重大資安漏洞(CVE-2026-20200)
【Security Vulnerability Alert】Cisco Integrated Management Controller contains a critical security vulnerability (CVE-2026-20200)

發布單位:圖資處網路系統組
日期範圍:2026/8/10 ~ 2027/2/10
 
發布單位:圖資處網路系統組
日期範圍:2026/8/10 ~ 2027/2/10
行政 行政公告
全體

轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 TWCERTCC-200-202608-00000003

[內容說明]
Cisco 旗下整合管理控制器( Integrated Management Controller,IMC)是一款專門為Cisco整合運算系統的伺服器設計管理工具,提供伺服器遠端監控、配置和管理功能。近日Cisco發布重大資安公告(CVE-2026-20200,CVSS:8.8),該漏洞允許經身分驗證的遠端攻擊者可能在受影響的底層作業系統上,執行任意程式碼或命令,並將權限提升至root。

[影響平台]
UCS C-Series M7 and M8 Rack Servers in standalone mode

[建議措施]
根據官方網站釋出的解決方式進行修補: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU

[參考資料]
1. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU
2. https://nvd.nist.gov/vuln/detail/CVE-2026-20200

Forwarded Taiwan Computer Network Emergency Response Team/Coordination Center Information Security Alert TWCERTCC-200-202608-00000003

[Content Description]
Cisco Integrated Management Controller (IMC) is a management tool designed for servers in Cisco Unified Computing System, providing remote monitoring, configuration, and management functions for servers. Recently, Cisco released a critical security advisory (CVE-2026-20200, CVSS: 8.8). This vulnerability allows an authenticated remote attacker to execute arbitrary code or commands on the affected underlying operating system and elevate privileges to root.

[Impacted Platform]
UCS C-Series M7 and M8 Rack Servers in standalone mode

[Recommended Actions]
Please perform patching according to the solution released on the official website: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU

[Reference]
1. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU
2. https://nvd.nist.gov/vuln/detail/CVE-2026-20200


相關附件
※為降低附件原始檔案遭搜尋引擎索引之風險,公告附件將由瀏覽器先下載至本機暫存後再開啟。請確認使用環境安全後,再決定是否開啟附件。
system_update_alt參考資料1
system_update_alt參考資料2
Top↑